CVE-2021-36030: Magento Commerce Improper Input Validation During Checkout Process Could Lead To Privilege Escalation
Published Sep 1, 2021
·Updated
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability during the checkout process. An unauthenticated attacker can leverage this vulnerability to alter the price of items.
Affected Software
6 affected components
Adobe Adobe Commerce>=2.3.0<=2.3.7
Adobe Adobe Commerce>=2.4.0<=2.4.2
Adobe Adobe Commerce=2.4.2-p1
Adobe Magento Open Source>=2.3.0<=2.3.7
Adobe Magento Open Source>=2.4.0<=2.4.2
Adobe Magento Open Source=2.4.2-p1
Remediation
Event History
Sep 1, 2021
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36030.
2
What is the severity of CVE-2021-36030?
The severity of CVE-2021-36030 is high, with a severity value of 7.5.
3
Which versions of Magento Commerce are affected by CVE-2021-36030?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected.
4
What is the impact of CVE-2021-36030?
An unauthenticated attacker can leverage this vulnerability to alter the price of items during the checkout process.
5
Is there a fix for CVE-2021-36030?
Yes, Adobe has provided a fix for CVE-2021-36030. Please refer to the reference link for more information.